'NovaCookies' Kit Steals Microsoft 365 Sessions for $320 a Month
Summary
A new adversary-in-the-middle (AitM) phishing service called 'NovaCookies' is now available for $320 per month. This service significantly reduces the technical expertise required for threat actors to conduct sophisticated attacks. NovaCookies can steal active Microsoft 365 session cookies, bypassing multi-factor authentication and offering more than just credential theft.
IFF Assessment
The availability of a low-barrier-to-entry phishing service that can steal session cookies and bypass MFA is bad news for defenders, as it empowers less sophisticated attackers to compromise valuable accounts.
Defender Context
Defenders should be aware of the rise of AitM phishing services like NovaCookies, which can circumvent traditional MFA by stealing active session cookies. Organizations need to implement stronger defenses beyond basic MFA, such as detecting unusual login patterns, monitoring for unauthorized session activity, and educating users about advanced phishing tactics.